hacker-news · Crawled Jul 19, 2026
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
1 IoCs 1 Actors
Read original article ↗
AI Summary
Russian state-sponsored threat actor UAC-0145, a sub-cluster of Sandworm affiliated with GRU, has been conducting cyberattacks against Ukrainian targets using the ClickFix social engineering technique. The attackers compromise websites and inject fake CAPTCHA checks that prompt users to execute malicious PowerShell commands, leading to malware infection. These commands download and execute malware such as GHETTOVIBE, SCOUTCURL, and COWARDDUCK, enabling data theft and remote control. The campaign also involves backdooring Android devices via malicious APKs distributed as security tools.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | GHETTOVIBE | Details → |
MITRE ATT&CK TTPs 41 techniques
T1003 OS Credential Dumping · Credential Access T1012 Query Registry · Discovery T1016 System Network Configuration Discovery · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1057 Process Discovery · Discovery T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1069.002 Domain Groups · Discovery T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1081 T1081 T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1090.002 External Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1120 Peripheral Device Discovery · Discovery T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1136.002 Domain Account · Persistence T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1217 Browser Information Discovery · Discovery T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access